A world engine controlled with Python

Omniweft

An early world engine with bounded worker lifecycle and explicit retry recovery. Late proposals cannot mutate the world; uncertain delivery can recover the original receipt without duplicating an edit.

Incubating. The room has Windows GPU evidence; native parenting and bounded queries have separate CPU records and are unsupported by the Python SDK. Linux physical GPU verification, physics and persistence remain unavailable.

Browser rendering of the retained Omniweft room geometry, with a table block and stool block between two walls.
Saved room / Browser view

Latest verified change · PR #22 / PR-015 ↗ · Merged

Worker recovery preserves the authority boundary

PR #21 adds bounded lifecycle, cancellation and explicit same-request retry. PR #22 preserves timed_out / DEADLINE_EXPIRED when restart first observes an expired ready proposal. The parent and native host must survive; process separation is not an OS sandbox.

Source checked . Documentation and retained evidence review, not a new runtime test.

Read change evidence ↗
Retained worker fixture · CPU / seed 7
PhaseStatusWorld revision
timeouttimed_out0
cancelledcancelled0
crashedcrashed0
supersededsuperseded0
replacementcommitted1
restartedcommitted2

Recorded statuses from the public archive. Prevented proposals leave the world at revision zero.

Download retained JSON · Source and limits ↗

Explore the actual output / 3D

Step inside the saved room.

Turn the room, inspect each object and compare a rejected change with an accepted move. These are the five unit-cube prefabs from the retained workshop scene.

Browser rendering of the retained Omniweft room geometry, with a table block and stool block between two walls.Saved scene / Unit-cube geometry

Can a rejected edit leave the room unchanged?

Compare the rejected change with the initial room, then inspect the accepted move. The scene version tells you which edit took effect.

  • Five objects from saved engine states
  • Three retained states to compare
  • Original native captures below

Five objects. Three retained room states.

A saved view is shown. Open 3D to inspect the evidence from another angle.

Geometry, transforms and revisions come from saved engine states. Colors and lighting distinguish the objects in this browser rendering. Original native engine captures are shown below. No new engine or AI run is implied.

In plain terms

Build a five-block room from Python, reject an out-of-bounds edit, then rearrange it within the allowed region.

Why it matters

Software tools need to know whether a requested change actually happened. Omniweft separates changes to the world from the optional graphics that display it.

Follow the example, step by step
  1. Connect locally

    A Python client starts an authenticated session with the native engine on the same computer.

  2. Submit a change

    Create or move an object. A rejected batch leaves the world unchanged.

  3. Read back the world

    Inspect the current in-memory state. If a response is uncertain, check the world before trying again.

Decision and trade-off

Retry the original request within its existing authority

Documented approach

The opt-in worker supervisor retains the exact prepared transaction after uncertain delivery. Explicit retry goes through the existing authenticated policy host and can recover the original receipt without duplicating the edit.

Alternative and scope

Restarting a worker with a new request key could repeat an edit that already committed. Replacement authoring therefore remains blocked while the outcome is uncertain. Legacy profiles keep their resync_only contract.

Cost of the choice

The fixed four-receipt, 2,000 ms retention window is bounded. Expiry requires reconciliation. The parent and volatile native host must survive; separate native persistence does not extend durability to this worker path.

What the evidence establishes

The retained CPU transport fixture loses a post-commit response and recovers the receipt after provider restart without duplicate creation or a second revision increment. PR #22 additionally corrects ready-proposal expiry on restart. No new engine run is claimed here.

Read the decision source (opens in a new tab)
Source-backed system map

Local control and downstream presentation

An architectural map of the room showcase: a scripted Python client submits scoped edits, the owner commits complete state, and optional Vulkan presentation captures the result. This diagram is editorial; the gallery holds actual output.

Local control and downstream presentationPYTHON CONTROL: Scripted Python client. Scoped permissions and budgets. CANONICAL WORLD: Owner-thread atomic transactions. Detached snapshots and receipts. OPTIONAL PRESENTATION: Detached room snapshots. Windows GPU evidence; Linux not_run. These are selected boundaries, not a sequential execution trace.
Selected documented boundaries, illustrated here; not a runtime screenshot or complete execution trace. Read the diagram source (opens in a new tab)
01

A worker proposes, the parent retains authority

The opt-in supervisor keeps at most eight request statuses and one active request, with at most two bounded children while draining old output. A worker receives no session token, epoch or prepared transaction. Timeout, cancellation, crash and supersession before submission prevent mutation; late output cannot revive a terminal proposal.

Submission crosses the cancellation boundary. Once it starts, cancellation returns too_late. If delivery is uncertain, the parent retains the exact prepared transaction for an explicit retry through policy.retry.v1. The existing four-receipt, 2,000 ms retention window does not extend on replay. Expired retention requires reconciliation, never a silently replaced request key.

PR #22 applies expiry before restart supersession. Restart just before the deadline can supersede a ready proposal; at or after the deadline it remains timed_out with DEADLINE_EXPIRED. Prepared and uncertain requests retain their recovery rules. Local statuses are not persistent, and this volatile policy host is not crash-durable.

02

Keep native history separate from worker recovery

The intervening merged slices add concurrent proposals and retained retries, bounded native undo/redo, recorded nonphysics command replay and native crash-safe persistence. Native history supports limited root tag and transform edits; it is not physical rewind or a remote editor endpoint.

Native persistence is a separate opt-in store with its own recovery contract. It does not make the worker supervisor or the volatile policy.retry.v1 host durable across a host crash. The worker article keeps that distinction explicit.

03

Ask only within the permission you hold

A native query combines required tags with an optional axis-aligned region. The host supplies an immutable read grant; tags never confer authority. A grant region must contain the complete cube, while the query region uses inclusive intersection.

Results arrive in UUID order, with bounded row and byte counts. A retained snapshot replays consistently after world edits. A successful new query replaces the earlier cursor, while an expired or closed session requires resynchronization.

The gallery plots real returned bounds from the Windows CPU proof. This does not add a remote endpoint: current Python SDK and policy gateways reject the native tag and query path. Session payload limits are not a global memory bound.

04

Move a parent, keep the relationship explicit

Native objects can now carry a generation-bearing parent link and an authored local transform. Reparenting can preserve either the object's world transform or its local transform. Moving a parent updates its descendants atomically.

The retained CPU example attaches child C to parent P, reparents C under Q without moving it in the world, rejects a cycle, moves Q and detaches C. Cycles, stale handles, ambiguous parent deletion and invalid numerical transforms reject the complete transaction. Parents require positive uniform world scale.

This native capability is separate from the Python room builder. Remote SDK and policy profiles reject hierarchy before scheduling. The CPU records establish neither physical-GPU behavior nor physics support.

05

A small room makes the control loop visible

A floor, back wall, side wall, table and stool are represented by five cubes. The scripted client assembles them through the existing east policy grant, then tries a batch containing a valid table move and a forbidden stool move. The rejection preserves the complete previous world. A corrected batch moves both objects within the permitted region.

This is an offline scripted provider using the public SDK, not a language model. The five live cubes consume 1,920 of the fixture's 2,048 retained charged bytes. Those numbers are deterministic policy accounting, not measured heap usage.

06

Permissions are checked before the world changes

The opt-in policy host has two separately credentialed principals with bounded write regions and explicit whole-world read grants. The coordinator checks complete cube bounds and commits world state and retained-memory sponsorship atomically.

Admission limits cover requests and working charges. The showcase uses the existing grant without expanding its permissions or quotas. After the sequence, idle observations check that outstanding request and working-byte usage return to zero.

07

A fixed-step owner feeds optional presentation

The earlier PR-006 slice adds a dedicated 60 Hz world owner and a separate scripted provider process. It caps catch-up at four executed ticks and reports discarded whole debt. Authoring revisions, simulation ticks and presentation stamps remain distinct.

The room showcase's optional Vulkan path renders detached snapshots and retains color, object-ID and depth attachments for revisions 3 and 4. Independent pixel checks compare expected object interiors and background while excluding a narrow expected-edge band.

08

Recovery is part of the interface

A lost or malformed mutation response can leave the result unknown even when the world changed. Legacy SDK profiles raise OutcomeUnknown and require explicit resynchronization. The separate opt-in retry profile retains a prepared request for explicit receipt recovery; neither path silently retries a change.

PR #12 integrated the Windows SDK compatibility correction after credential renewal. The original control host remains available alongside the newer agents and policy fixtures.

09

What was reviewed and what was actually run

The current source was checked on 30 September 2026 through PR #22. The worker table reads the retained PR-015-RESTART CPU archive. Earlier query evidence was reviewed on 21 September 2026 at 921c167980a0c2459c40e74d8d084e84437a0ce0. GitHub records native-query PR #16 as merged on 20 September, despite candidate wording in its evidence documents. Query pages belong to runtime 3b32f812232608af0203d579a9cb89ce9f71173c. Earlier hierarchy diagrams retain runtime 9630e3bf8dd934d7b91b6f06d0e458272d5d6e1c. This refresh reads their saved records without executing the engine.

The retained room evidence belongs to runtime de3d52e8a4937a1eae59c3a41b22f791fdd00149. It reports Windows CPU and physical-GPU proofs, regression proofs and hosted Windows/Linux checks. The gallery encodes original color readback bytes as lossless PNG and verifies decoded pixels against their recorded hashes. This portfolio refresh did not rerun the native engine.

10

What is still experimental

Linux physical-GPU verification remains not_run. Physics, richer mesh, voxel and pixel editing, and performance targets remain future slices. Bounded native persistence is implemented separately. This tiny fixture is not a finished editor or game.

Native read grants and query filtering do not extend the fixed two-principal remote policy fixture. General fairness, remote queries and arbitrary agent safety remain unestablished. No released Python installation package, language-model execution or production-readiness claim is made.

Continue the engineering story
Engineering history
Source snapshot

Inspect the checked source

Evidence reviewed . Individual decisions and captured examples retain their own source revisions and limitations.

Read the checked README (opens in a new tab)

Technical footprint

Repository-described tools and interfaces, not a proficiency rating.

  • C++20
  • Python
  • SDL3 / Vulkan
  • Scoped permissions